Obligations of Subjects of Financial Monitoring in Kazakhstan under Law No. 191-IV in 2026: Who Is on the List, Threshold and Suspicious Transactions, Customer Due Diligence, Reporting Deadlines to the AFM, Internal Control Rules and Fines

Obligations of Subjects of Financial Monitoring in Kazakhstan under Law No. 191-IV in 2026: Who Is on the List, Threshold and Suspicious Transactions, Customer Due Diligence, Reporting Deadlines to the AFM, Internal Control Rules and Fines

A subject of financial monitoring (SFM) — the statutory term for a reporting entity — is an organisation or individual listed in paragraph 1 of Article 3 of Law of the Republic of Kazakhstan No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction” (Law No. 191-IV, the AML/CFT/CPF Law), on which the Law imposes duties to detect and report transactions in money and other property to the Agency of the Republic of Kazakhstan for Financial Monitoring (AFM), the authorised body for financial monitoring (Kazakhstan’s financial intelligence unit). In 2026 the list has 27 items, three of which have been deleted, and it covers banks, exchanges, insurers, pension funds, professional securities-market participants, notaries, advocates and legal consultants, accounting and audit firms, gambling operators, postal money-transfer operators, microfinance (including pawnshops) and payment organisations, unlicensed lessors, dealers in precious metals and jewellery, real-estate agents, the Social Health Insurance Fund, participants of the Astana International Financial Centre (AIFC), the State Corporation, mobile operators and — since 1 May 2026 — five categories of digital-asset operators and issuers. The duties of every SFM fall into six blocks: customer due diligence (Articles 5–9); detection of threshold transactions at fixed amounts from KZT 1,000,000 to KZT 500,000,000 and of suspicious transactions with no threshold (Article 4); reports to the AFM through the personal account on Form FM-1 within fixed deadlines (Articles 10, 10-1 and 13); internal control rules (ICR) with a responsible officer and trained staff (Article 11); freezing of transactions and refusal of service to listed persons (Articles 12, 12-1 and 13); and record-keeping for at least five years (Article 11). For breaches, Article 214 of the Code of Administrative Offences (CAO) provides fines from 30 to 1,800 monthly calculation indices (MCI) — at the 2026 MCI of KZT 4,325 that is KZT 129,750 to KZT 7,785,000 — with suspension of a licence or a ban on activity for up to three years for a third breach within a year.

Key facts. First: Law No. 191-IV applies in the wording in force as at 13 August 2026; the central reform is Law No. 219-VIII of 19 September 2025, in force since 20 November 2025, which renamed the Law, introduced the concept of a customer’s suspicious activity (two or more suspicious transactions) with its own three-working-day reporting deadline (Article 10-1) and created preventive control by the AFM without a visit to the entity (Article 14-1). Second: since 1 May 2026, under Law No. 259-VIII of 16 January 2026, the list includes operators of exchange of unsecured digital assets, operators of digital financial asset platforms, operators of digital-asset trading platforms, issuers of digital financial assets and participants of the National Bank’s special regulatory regime (sub-paragraphs 23)–27) of paragraph 1 of Article 3). Third: registration in the personal account on the AFM portal is mandatory for every SFM whether or not it has any reportable transactions (paragraph 2-1 of Article 10; Rules for the Personal Account approved by AFM Order No. 18 of 8 December 2025). Fourth: Article 214 of the CAO applies in the wording of Law No. 247-VIII of 30 December 2025 (in force since 2 March 2026) and contains 19 offences — from breach of record-keeping rules (30–280 MCI) to a third breach within a year (200–1,800 MCI with suspension of a licence for up to six months, suspension of activity for up to three months or a ban on activity for up to three years). Fifth: according to the AFM Chairman’s report to the President on 12 January 2026, in 2025 the financial sector terminated business relationships with 2,000 companies and 56,000 individuals on suspicion of laundering; the Eurasian Group (EAG) upgraded Kazakhstan’s ratings on four FATF Recommendations in May 2026, and Kazakhstan is not on the FATF list of jurisdictions under increased monitoring of 19 June 2026.

What a Subject of Financial Monitoring Must Do: A Map of Duties and Consequences

The duties of a subject of financial monitoring form a system of six interlocking requirements of Law No. 191-IV, most of which carry their own offence in Article 214 of the CAO. The table below maps the duties, provisions, deadlines and fines for a medium-sized enterprise (the third scale of Article 214 — medium-sized business entities); each row is developed in the sections that follow.

Duty of the SFM

Provision of Law No. 191-IV

Deadline

Fine for a mediu­m-sized enterprise (Arti­cle­ 214 CAO)

Register in the AFM personal account; for legal consu­lta­nts, lessors, jewellers and rea­l-e­state agents — file a noti­fica­tion of comme­nce­ment of activity

Paragraph 2-1 of Arti­cle­ 10; paragraph 3 of Article 3

Noti­fica­tion — before starting activity; no statutory deadline for regi­stra­tion in the account

No separate offence in Arti­cle­ 214; activity without noti­fica­tion — Arti­cle­ 463 CAO (40 MCI for a mediu­m-sized ente­rprise)

Conduct due diligence on the customer, its repre­senta­tive and beneficial owner

Arti­cle­s 5–9

Before esta­bli­shing a business rela­tio­nship; update within 15 working days once doubts arise

Part 8 — 280 MCI (KZT 1,211,000)

Report a threshold tra­nsa­ction

Paragraph 1 of Article 4; paragraph 2 of Article 10

No later than the working day following the tra­nsa­ction

Parts 12–13 — 260–300 MCI

Report a suspicious tra­nsa­ction

Paragraph 3 of Article 4; paragraph 2 of Article 13

Before the tra­nsa­ction; if recognised afterwards — within 24 hours

Parts 2–3 — 290–330 MCI

Report a customer’s suspicious activity

Arti­cle­ 10-1

No later than three working days after reco­gni­tion

No separate offence in Arti­cle­ 214; the tra­nsa­ctions making it up — parts 2–3

Answer an AFM request

Paragraph 3-1 of Article 10

Three working days; for the analysis of a suspicious tra­nsa­ction — no later than the working day on which the request is received

Parts 4–5 — 280–300 MCI

Adopt ICR, appoint a respo­nsible officer, train and test staff

Arti­cle­ 11; AFM Orders No. 4 and No. 6 of August 2021

No express statutory deadline — in practice before the first tra­nsa­ction; the test — before taking up the function

Parts 11, 15, 16 — 210–345 MCI

Freeze tra­nsa­ctions of persons on the terro­rist-fi­nancing and prolife­ration-fi­nancing lists

Arti­cle­s 12, 12-1; paragraph 1-1 of Article 13

Within 24 hours of publi­ca­tion of the list

Part 9 — 330 MCI (KZT 1,427,250)

Refuse service where due diligence is impo­ssi­ble; report the refusal

Paragraph 1 of Article 13

Report — no later than the next working day

Part 10 — 280 MCI

Keep records and never disclose that a report has been filed

Paragraphs 4–5 of Article 11

Five years from the end of the rela­tio­nship or the tra­nsa­ction

Parts 1 and 17 — 210–330 MCI

Author’s assessment: the defining feature of Kazakhstan’s regime is dual-track reporting. Unlike many jurisdictions, where mandatory reporting is built around suspicious transactions and, at most, large cash transactions, Law No. 191-IV requires reports of threshold transactions across a wide range of transaction types — cash and non-cash alike — regardless of any suspicion, and that creates two separate grounds for a penalty: for a missed threshold transaction (parts 12–13 of Article 214 CAO) and for a missed suspicious one (parts 2–3). For a company that has only just acquired SFM status this means that, even with no doubtful customers at all, the flow of mandatory reports to the AFM begins with the first large payment. Which businesses in Kazakhstan become SFMs at the moment of registration, and which notifications that requires, is examined in Permits and Notifications in Kazakhstan in 2026.

Which Instruments Govern the Duties of Subjects of Financial Monitoring and How Law No. 191-IV Has Been Amended

The legal framework of financial monitoring in Kazakhstan is a five-tier hierarchy: Law No. 191-IV itself; the codes on liability (the Code of Administrative Offences and the Criminal Code); the orders of the AFM as the authorised body; the acts of sector regulators on internal control rules for “their” sectors; and the acts of the President and the Government on strategy and risk-mitigation measures. No tier displaces another: the Law sets the duties, the AFM orders set the form and technique of performing them, the sector acts fill in the detail of the ICR, and the codes attach the sanctions. All references to statutory and subordinate provisions follow the consolidated texts of the Adilet legal information system, read on 10 September 2026; the commencement dates of amendments are cross-checked against the notes of the Paragraph information system.

Tier

Instrument and parti­cu­lars

What it governs for SFMs

1. Law

Law of the Republic of Kazakhstan No. 191-IV of 28 August 2009 “On Cou­ntera­cting the Lega­lisa­tion (Lau­nde­ring) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Pro­life­ration of Weapons of Mass Destru­ction” — published 8 September 2009, in force since 9 March 2010; text as amended as at 13 August 2026

The list of SFMs (Arti­cle­ 3), threshold and suspicious tra­nsa­ctions (Arti­cle­ 4), due diligence (Arti­cle­s 5–9), reporting (Arti­cle­s 10, 10-1), internal control and risk assessment (Arti­cle­s 11, 11-1), targeted financial sanctions (Arti­cle­s 12, 12-1), beneficial owners (Arti­cle­s 6-1, 12-3), refusal and freezing (Arti­cle­ 13), state control (Arti­cle­s 14, 14-1)

2. Codes

Code of Admi­nistra­tive Offences No. 235-V of 5 July 2014, Arti­cle­s 214 (in the wording of Law No. 247-VIII of 30 December 2025, in force since 2 March 2026), 214-1 and 463; Criminal Code­ No­. 226-V of 3 July 2014, Arti­cle­s 218 and 218-1

Admi­nistra­tive fines from 30 to 1,800 MCI and suspension of activity; criminal liability for laundering — up to 10 years’ impri­so­nment with confi­sca­tion

3. AFM orders

Orde­r No­. 13 of 22 February 2022 (Rules for Providing Info­rma­tion and indicators of suspicious tra­nsa­ctions; as reworded by Orde­r No­. 22 of 23 December 2025, in force since 1 April 2026, with the amendments of Orde­r No­. 12 of 16 June 2026, in force since 12 July 2026); Orde­r No­. 4 of 6 August 2021 (ICR requi­re­ments for the non-fi­na­ncial sector; as reworded by Orde­r No­. 15 of 25 November 2025, in force since 12 December 2025); Orde­r No­. 6 of 9 August 2021 (training and testing; as reworded by Orde­r No­. 27 of 29 December 2025, in force since 20 January 2026); Orde­r No­. 18 of 8 December 2025 (personal account; in force since 26 December 2025); Orde­r No­. 5 of 25 September 2023 (register of beneficial owners; in force since 11 September 2023, amended by Orde­r No­. 21 of 23 December 2025 with effect from 17 January 2026)

Form FM-1 and tra­nsmi­ssion channels, suspicion indicator code­s 11–27, requi­re­ments for the respo­nsible officer, the AML knowledge test, regi­stra­tion in the personal account, access to the register of beneficial owners

4. Sector acts on ICR

Resolution of the Board of the Agency for Regulation and Deve­lo­pment of the Financial Market (ARDFM) No. 18 of 22 March 2020 (ICR for seco­nd-tier banks, branches of non-re­si­dent banks and the National Postal Operator; Requi­re­ments as reworded by Resolu­tion No­. 74 of 20 April 2026); ARDFM and National Bank acts for insurers, pro­fe­ssional secu­ritie­s-market parti­ci­pants, payment orga­nisa­tions and digi­tal-a­sset operators; Order of the Minister of Justice No. 705 of 28 November 2025 (notaries; in force since 13 December 2025); Order of the Acting Minister of Tourism and Sport No. 250 of 19 December 2025 (gambling and lotteries; in force since 6 January 2026); Order of the Deputy Prime Minister — Minister of Artificial Inte­lli­gence and Digital Deve­lo­pment No. 192/НҚ of 8 April 2026 (postal operators; in force since 24 April 2026)

Content of the ICR, frequency of custo­me­r-data updates, remote identi­fica­tion, training programmes

5. Acts of the President and the Government

Pre­side­ntial Decree­ No­. 1038 of 6 October 2022 approving the Concept for the Deve­lo­pment of Financial Monitoring 2022–2026; Government Resolu­tion No­. 934 of 7 November 2025 approving measures to reduce the risks of laundering (in force since 20 November 2025)

Target indicators (90 % of SFMs in the AFM info­rma­tion system by 2026); 44 mea­sures with deadlines running to December 2027: new suspicion indi­ca­tors, a register of high-risk crypto­-wa­llets, metho­dolo­gical guidance for banks, rea­l-e­state agents and jewellers

The amendment history of Law No. 191-IV. Since 2020 the Law has been amended by more than ten laws; the table lists the nine that changed the duties of SFMs and the law that rewrote Article 214 of the CAO. Adoption, first official publication and commencement dates are shown separately, because in Kazakhstan they almost never coincide: the standard formula “on the expiry of sixty calendar days after the day of first official publication” means commencement on the 61st day after publication.

Law

Adopted

Published

In force

Changes for SFMs

No. 325-VI

13 May 2020

14 May 2020

15 November 2020

Targeted financial sanctions for pro­life­ration financing (Arti­cle­ 12-1), protection of charities (Arti­cle­ 12-2), reco­gni­tion of suspicious tra­nsa­ctions under the entity’s own ICR, enhanced due diligence for customers from countries with deficient imple­menta­tion of FATF Reco­mmenda­tions

No. 73-VII

18 November 2021

19 November 2021

19 January 2022

Noti­fica­tion of comme­nce­ment and termi­na­tion of activity for legal consu­ltants (other than advo­ca­tes), lessors, jewellers and rea­l-e­state agents (paragraph 3 of Article 3)

No. 131-VII

1 July 2022

4 July 2022

3 September 2022

Duty of legal entities to identify their own beneficial owners (Arti­cle­ 12-3); Arti­cle­ 214-1 CAO on the liability of legal entities for laundering

No. 23-VIII

12 July 2023

13 July 2023

12 September 2023

Register of beneficial owners of legal entities (Arti­cle­ 6-1), as part of the asse­t-re­covery legi­sla­tion; Arti­cle­ 218-1 of the Criminal Code

No. 113-VIII

5 July 2024

6 July 2024

5 September 2024

Aims, tasks and principles of the Law (Arti­cle­s 2-1, 2-2); refi­ne­ments to Article 3 and to the AFM’s functions (Arti­cle­s 15–17)

No. 219-VIII

19 September 2025

20 September 2025

20 November 2025

New title of the Law; a customer’s suspicious activity (Arti­cle­ 10-1); preventive control without a visit (Arti­cle­ 14-1); new wording of Arti­cle­ 11-1 on risk asse­ssment; by the footnotes of the conso­li­dated text the amendments touched 28 articles, including two new ones

No. 247-VIII (CAO)

30 December 2025

31 December 2025

2 March 2026

New wording of Arti­cle­ 214 CAO: 19 o­ffe­nces and four fine scales

No. 256-VIII

9 January 2026

10 January 2026

11 July 2026

Digi­talisa­tion: Arti­cle­s 2-1, 6-1, 14-1, 16–18 (service of documents through the personal account)

No. 259-VIII

16 January 2026

17 January 2026

1 May 2026 (AML/CFT pro­vi­sions)

Five categories of digi­tal-a­sset operators and issuers on the SFM list (su­b-para­graphs 23)–27) of paragraph 1 of Arti­cle­ 3); thresholds for digi­tal-a­sset tra­nsa­ctions; register of cry­pto-wa­llets used for criminal purposes

No. 311-VIII

12 June 2026

13 June 2026

13 August 2026

New wording of the poli­ti­cally exposed person criterion for heads of inte­rna­tional orga­nisa­tions esta­bli­shed by states under inte­rna­tional treaties

Author’s assessment: as of September 2026 the regime has stabilised, but three duties have only just begun to apply. The first is reporting of suspicious activity under Article 10-1 (since 20 November 2025); the second is the updated suspicion indicators of AFM Order No. 13 (since 1 April 2026); the third is SFM status for digital-asset operators (since 1 May 2026). These are precisely the three areas in which the AFM, under Government Resolution No. 934, is drafting new typologies and indicators during 2026, so ICR adopted before November 2025 need revision. How the licensing regime for digital-asset operators — SFMs since May 2026 — is structured is described in Digital Assets and Mining in Kazakhstan 2026.

Who Is a Subject of Financial Monitoring in Kazakhstan in 2026 and Who Supervises It

The list of subjects of financial monitoring is the closed list in paragraph 1 of Article 3 of Law No. 191-IV: SFM status arises neither by a decision of the AFM nor by registration in the personal account, but automatically — from the moment a person begins the activity named in one of the sub-paragraphs. State bodies are not SFMs (paragraph 2 of Article 3). The list contains 27 sub-paragraphs; sub-paragraphs 14) and 17) were deleted earlier, and sub-paragraph 20) was deleted with effect from 1 May 2026 by Law No. 259-VIII, which added sub-paragraphs 23)–27).

Group

Sub-pa­ra­graphs of paragraph 1 of Article 3

Who is covered

Banking and payments

1), 10), 11), 12)

Seco­nd-tier banks, branches of non-re­si­dent banks, orga­nisa­tions carrying out certain banking operations (except the interbank transfer system operator and cash-co­llectio­n-only entities); postal operators providing money transfers; orga­nisa­tions carrying on micro­fi­nance activity — under Arti­cle­ 3 of Law No. 56-V of 26 November 2012 “On Micro­fi­nance Activity” these are micro­fi­nance orga­nisa­tions, pawnshops and credit partne­rships; payment orga­nisa­tions

Financial market

2), 3), 4), 5)

Exchanges, clearing orga­nisa­tions, commo­dity-e­xchange brokers, clearing centres of commodity exchanges; insurance (rei­nsu­rance) orga­nisa­tions, insurance brokers, mutual insurance societies, the Export Credit Agency, branches of non-re­si­dent insurers; the Unified Accu­mula­tive Pension Fund and voluntary accu­mula­tive pension funds; pro­fe­ssional secu­ritie­s-market parti­ci­pants and the central depository

Legal and accounting pro­fe­ssions

6), 7), 8)

Notaries performing notarial acts involving money and property; advocates, legal consu­ltants and other inde­pe­ndent legal spe­cia­lists — when acting for a client in rea­l-e­state tra­nsa­ctions, the management of money, securities and accounts, the accu­mula­tion of funds to create and run companies, and the creation, purchase, sale and management of legal entities; accounting orga­nisa­tions, pro­fe­ssional accou­ntants in private practice, audit orga­nisa­tions

Goods and services markets

9), 13), 15), 16), 22)

Gambling and lottery operators; individual entre­pre­neurs and legal entities acting as lessors without a licence; dealers in precious metals, precious stones and jewellery; inte­rmedia­ries in rea­l-e­state sale and purchase (rea­l-e­state agents); mobile operators

Qua­si-pu­blic sector and the AIFC

18), 19), 21)

The Social Health Insurance Fund; AIFC parti­ci­pants carrying on activities determined by the Astana Financial Services Authority (AFSA) in agreement with the AFM; the State Corpo­ra­tion “Go­ve­rnment for Citizens”

Digital assets (since 1 May 2026)

23), 24), 25), 26), 27)

Operators of exchange of unsecured digital assets; operators of digital financial asset platforms; operators of digi­tal-a­sset trading platforms; issuers of digital financial assets; parti­ci­pants of the National Bank’s special regulatory regime for digital assets

Three start-up duties of SFM status. The first is a notification of commencement of activity: advocates are exempt, but legal consultants and other independent legal specialists, unlicensed lessors, dealers in precious metals and jewellery and real-estate agents must notify the AFM of the commencement or termination of their activity under Law No. 202-V of 16 May 2014 “On Permits and Notifications” (paragraph 3 of Article 3; item 35 of Annex 3 to Law No. 202-V); the AFM keeps the state electronic register of such notifications (sub-paragraphs 13-1) and 13-2) of Article 16). The second is registration in the personal account on the AFM portal, mandatory for all SFMs whether or not they have reportable transactions (paragraph 2-1 of Article 10): under the Rules for the Personal Account approved by AFM Order No. 18 of 8 December 2025, the entity enters its IIN or BIN, the portal checks the type of activity automatically, and if there is a mismatch the entity sends supporting documents (a licence, a notification, a qualification certificate, the charter) within three working days, after which the AFM decides on access within three working days. The third is uploading to the personal account the results of the risk-exposure assessment of the entity’s services, the ICR and the test certificate (paragraph 8 of the Rules).

Who sets the ICR requirements and who inspects. The Law divides competence along two lines: the ICR requirements (paragraph 3-2 of Article 11) and state control (Article 14). The table shows how that works for five typical categories.

Parameter

Seco­nd-tier bank (su­b-para­. 1))

Notary (su­b-para­. 6))

Legal consu­ltant, accounting firm (su­b-para­s. 7), 8))

Rea­l-e­state agent, jeweller, lessor (su­b-para­s. 13), 15), 16))

Digi­tal-a­sset exchange operator (su­b-para­. 23))

ICR requi­re­ments set by

ARDFM in agreement with the AFM (Resolu­tion No­. 18 of 22 March 2020)

Ministry of Justice in agreement with the AFM (Orde­r No­. 705 of 28 November 2025)

AFM (Orde­r No­. 4 of 6 August 2021)

AFM (Orde­r No­. 4 of 6 August 2021)

National Bank in agreement with the AFM

State control by

ARDFM

Ministry of Justice

AFM (except audit orga­nisa­tions and advocates)

AFM

The regulator under the digi­tal-a­ssets legi­sla­tion, within its competence

Noti­fica­tion of comme­nce­ment to the AFM

No (ARDFM licence)

No (licence)

Yes for legal consu­ltants and inde­pe­ndent spe­ciali­sts; no for advocates and accou­ntants

Yes

No (au­thori­sation under the digi­tal-a­ssets legi­sla­tion)

Regi­stra­tion in the AFM personal account

Mandatory

Mandatory

Mandatory

Mandatory

Mandatory

Respo­nsible officer

Head of a unit with an impeccable reputation (paragraph 3 of Arti­cle­ 11)

The notary personally

Head of a unit; an individual entre­pre­neur appoints himself or herself

Head of a unit; an individual entre­pre­neur appoints himself or herself

Under National Bank requi­re­ments

AML knowledge test

Respo­nsible officer — before taking up the function; result valid three years

Sole pra­cti­tioner — within three months of starting activity

Respo­nsible officer — before taking up the function; sole pra­cti­tioner — within three months

Respo­nsible officer — before taking up the function; sole pra­cti­tioner — within three months

Respo­nsible officer — before taking up the function

AFM preventive control without a visit (Arti­cle­ 14-1)

No

No

Yes

Yes

No

Author’s assessment: the greatest risk of an inadvertent breach lies with businesses that do not think of themselves as “financial”. An accounting firm keeping clients’ books, a law firm registering LLPs for clients, a real-estate agency or a jewellery shop becomes an SFM by virtue of its activity and falls under the AFM’s direct control — including preventive control without a visit, in which a compliance notice is issued on the basis of state information systems without any inspector calling. A foreign investor opening a company in Kazakhstan in these fields should build SFM status into the launch plan alongside registration and tax accounting; the LLP registration procedure and the related duties are described in LLP (TOO) in Kazakhstan for Foreigners 2026.

Which Transactions Are Threshold Transactions and at What Amounts They Must Be Reported

A threshold transaction is a transaction in money or other property that an SFM must report to the AFM solely because its amount equals or exceeds a threshold fixed in paragraph 1 of Article 4 of Law No. 191-IV — whether or not the transaction shows any indicator of suspicion. The thresholds are expressed in tenge; for foreign-currency transactions the equivalent at the market rate on the day of the transaction applies, and for unsecured digital assets the equivalent at their market value on that day. A threshold transaction is reported no later than the working day following the day it is carried out (paragraph 2 of Article 10). Below is the complete scale of thresholds in the wording in force since 1 May 2026.

Threshold, KZT

Tra­nsa­ctions (su­b-para­graph of paragraph 1 of Article 4)

Form of settlement

1,000,000

Receipt of winnings from betting, gambling in gambling esta­bli­shments and lotteries, including electronic ones; purchase and sale of cultural valuables, their import and export (su­b-para­. 1))

Cash for cultural valuables; any form for winnings

3,000,000

Pawnshop tra­nsa­ctions in money, secu­ri­ties, precious metals and stones, jewellery and other valuables (su­b-para­. 1-1))

Cash and non-cash

5,000,000

Transfers abroad to anonymous accounts and receipts from anonymous accounts; purchase and sale of jewellery; credits and transfers from persons regi­ste­red, resident or located in an offshore zone or holding an account with a bank in an offshore zone, and tra­nsa­ctions with such persons; money tra­nsa­ctions to or from operators of exchange of unsecured digital assets, tradi­ng-pla­tform operators, National Bank spe­cial-re­gime parti­ci­pants and AIFC licensees; credits and transfers of unsecured digital assets and tra­nsa­ctions of such operators’ clients (su­b-para­. 2))

Cash and non-cash

7,000,000

Payments and transfers of money to another person free of charge; tra­nsa­ctions in shares and units of investment funds, including those issued on a digital financial asset platform (except repo on the organised market); tra­nsa­ctions in digital financial assets under sub-pa­ra­graphs 1) and 2) of Arti­cle­ 5 of the Law on Digital Assets (su­b-para­. 3))

Cash and non-cash

10,000,000

Purchase, sale and exchange of foreign currency through exchange offices; withdrawal and deposit of cash to a bank account, issue and receipt of cash; tra­nsa­ctions of legal entities registered less than three months earlier; insurance payouts and premiums in cash; voluntary pension contri­bu­tions and payouts in cash; cash payment under contracts for work, carriage, forwa­rding, storage, commission and trust management (except safe­-de­posit rental); receipt of money under a cheque or bill in cash; import and export of cash currency, bills and cheques, except by the National Bank, banks and the National Postal Operator (su­b-para­. 4))

As specified in the sub-pa­ra­graph

45,000,000

Receipt and provision of property under a financial lease; tra­nsa­ctions in bonds and government securities (except repo); tra­nsa­ctions in digital financial assets under paragraph 3 of Arti­cle­ 5 of the Law on Digital Assets (su­b-para­. 5))

Cash and non-cash

50,000,000

Tra­nsa­ctions of a customer that received a loan under National Fund busine­ss-fi­nancing programmes (su­b-para­. 6)); rea­l-e­state tra­nsa­ctions tra­nsfe­rring title (su­b-para­. 8)); sale and purchase of movable property tra­nsfe­rring title, and of precious metals and stones, except sales of refined gold and other sales to the National Bank, purchases of reference samples and purchases from subsoil users holding a mining licence (su­b-para­. 9))

Cash and non-cash

100,000,000 in forei­gn-cu­rrency equivalent

Cro­ss-bo­rder payments and transfers to and from a customer’s bank account (su­b-para­. 7))

Non-cash

500,000,000

Exchange tra­nsa­ctions in commo­di­ties on a commodity exchange (su­b-para­. 10))

Non-cash

Four rules for applying the thresholds. First, the threshold is compared with the amount of the individual transaction, not with the customer’s turnover over a period: systematic sub-threshold transactions are not themselves threshold transactions, but they constitute the “structuring” indicator of suspicion (code 24 of Annex 2 to AFM Order No. 13). Second, the duty to report rests with every SFM through which the transaction passes: a KZT 50,000,000 real-estate deal generates a report from the notary certifying the contract, from the real-estate agent acting as intermediary and from the bank processing the payment. Third, a threshold transaction is reported in every case, not only where the customer has failed to explain its economic rationale; examining the rationale belongs to mandatory scrutiny under paragraph 4 of Article 4. Fourth, Law No. 191-IV neither defines “offshore zone” for the KZT 5,000,000 threshold nor refers to a specific list — the dedicated Ministry of Finance list for the purposes of the AML Law (Order No. 52 of 10 February 2010) was repealed with effect from 15 November 2020 — so the list the SFM applies should be set out in its ICR in the light of AFM guidance and sector lists (for example, ARDFM Resolution No. 8 of 24 February 2020 for banking and insurance).

Author’s assessment: the scale of thresholds is the most frequent source of omissions among non-financial SFMs. A real-estate agent earning a commission monitors the price of the property, not the fee: a flat sold for KZT 55,000,000 is a threshold transaction for the agent, the notary and the bank at once; a bank processing a customer’s gratuitous transfer of KZT 7,000,000 reports under sub-paragraph 3); and a jewellery salon reports every sale from KZT 5,000,000 under sub-paragraph 2), even where the buyer paid by card. Companies opening an account with a bank in Kazakhstan for foreign-trade settlements should keep in mind the KZT 100,000,000-equivalent threshold for cross-border transfers, which the bank applies automatically: the practical steps for a non-resident opening an account are described in Opening a Bank Account in Kazakhstan for a Foreign Company and a Non-Resident, and the interaction with currency control in Currency Control in Kazakhstan 2026.

What Counts as a Suspicious Transaction and a Customer’s Suspicious Activity, and How They Are Detected

A suspicious transaction is a customer’s transaction — including an attempted transaction, one in progress and one already completed — in relation to which suspicions arise that the money or other property used is the proceeds of criminal activity, or that the transaction itself is aimed at laundering the proceeds of crime, financing terrorism, financing the proliferation of weapons of mass destruction or other criminal activity (sub-paragraph 1) of Article 1 of Law No. 191-IV). Unlike threshold transactions, suspicious transactions are subject to financial monitoring regardless of their form and amount (paragraph 3 of Article 4). It is the SFM itself that recognises a transaction as suspicious — either under the programmes implementing its ICR or as a result of mandatory scrutiny. A customer’s suspicious activity is a new concept introduced by Law No. 219-VIII: a set of two or more suspicious transactions (sub-paragraph 4-1) of Article 1), reported separately under Article 10-1.

Four grounds for mandatory scrutiny (paragraph 4 of Article 4). An SFM must examine a transaction if it is complex or unusual in nature, has no obvious economic rationale or lawful purpose, or is unusually large for the customer; is accompanied by actions aimed at evading due diligence or monitoring; is presumably aimed at cashing out the proceeds of crime; or is carried out with persons registered or resident in a state that fails, or insufficiently, to implement the FATF Recommendations, or through an account with a bank in such a state — according to the list compiled by the AFM on the basis of FATF documents and posted on its website. Transactions that match typologies and schemes approved by the AFM and posted on its website are also subject to monitoring (paragraph 5 of Article 4). The outcome of scrutiny is recorded: under paragraph 22 of the ICR Requirements for the non-financial sector (AFM Order No. 4), a decision to treat a transaction as suspicious is documented with its date and grounds.

Indicators of suspicion. Annex 2 to AFM Order No. 13 of 22 February 2022, in the wording in force since 1 April 2026, contains 17 groups of indicators with codes 11–27, which are entered on Form FM-1.

Code

Group of indicators (Annex 2 to AFM Orde­r No­. 13)

11

Payments and transfers by indi­vi­duals inco­nsi­stent with their income and social status

12

Regi­stra­tion of assets in the names of nominees

13

Use of legal entities and individual entre­pre­neurs through sham tra­nsa­ctions

14

Large turnover of a company or entre­pre­neur without comme­nsu­rate income or genuine activity

15

Use of structures whose beneficial owners are hard to determine: offshore entities, trusts, multi­-layer chains

16

Digi­tal-a­sset tra­nsa­ctions and wallets linked to illegal activity

17

Cash tra­nsa­ctions: deposits, cash-outs, frequent large ATM withdra­wals, especially abroad; cash couriers

18

Forei­gn-trade payments without economic benefit

19

Cro­ss-bo­rder tra­nsa­ctions through high-risk juri­sdi­ctions and informal transfer systems

20

Suspicious tra­nsa­ctions in securities and on exchanges

21

Concea­lment of the illegal origin of funds through bets, sham loans, leasing, insurance and pension contri­bu­tions

22

High-risk forei­gn-e­xchange tra­nsa­ctions under the national risk asse­ssment, including capital flight and evasion of currency legi­sla­tion

23

Movement of funds of non-profit and charitable orga­nisa­tions

24

Deposit tra­nsa­ctions, including systematic sub-thre­shold tra­nsa­ctions (stru­ctu­ring)

25

Acqui­si­tion of property, including luxury goods, for cash or in a single payment

26

Investment in legitimate business without sufficient income

27

Other unusual tra­nsa­ctions: property of une­xplained origin, pro­fe­ssional lau­nde­rers, companies profiting from raising money

Deadlines. A report of a suspicious transaction is filed before the transaction is carried out; where the transaction is recognised as suspicious only after it has been carried out, no later than 24 hours after recognition (paragraph 2 of Article 13), and the interval between execution and recognition may not exceed the review frequency fixed in the ICR. A report of a customer’s suspicious activity is filed no later than three working days after the day the activity is recognised as suspicious (Article 10-1). Transactions matching AFM typologies are reported no later than the working day following recognition (paragraph 2 of Article 10).

Author’s assessment: the list of indicators will keep growing in 2026, and the ICR must allow for that.Government Resolution No. 934 of 7 November 2025 instructs the AFM, between March and June 2026, to add to Order No. 13 indicators for transactions involving “drops” — persons who have given third parties access to their bank accounts or payment instruments — for cash-outs, sham loans, purchases and sales of vehicles and the use of legal entities and foreign structures for criminal purposes, and to build a register of high-risk crypto-wallets by December 2026. For an SFM this means that the monitoring programme must contain a mechanism for updating codes and typologies rather than a fixed list; according to the AFM’s report for 2025, it blocked more than 1,100 illegal online crypto-exchange services and 20,000 drop cards, so customer transactions showing the features of codes 16 and 17 are the first thing an inspection looks at.

How Customer Due Diligence Is Conducted and When Enhanced Measures Apply

Customer due diligence is the set of measures laid down in Article 5 of Law No. 191-IV that an SFM must apply to a customer, its representative and its beneficial owner when establishing a business relationship, when carrying out transactions subject to monitoring (including suspicious ones), and when doubts arise about the reliability of information obtained earlier (paragraph 2 of Article 5). The identification measures and the establishment of the purpose of the relationship are completed before the business relationship is established (Article 6) and before a transaction is carried out if due diligence has not been performed earlier (Article 7).

The seven due-diligence measures (sub-paragraphs 1), 2), 2-1), 2-2), 4), 5) and 6) of paragraph 3 of Article 5). First, identification of an individual by IIN, by the particulars of the identity document (where there is no IIN) and by legal address. Second, identification of a legal entity by its state-registration data, BIN, nature of activity and address. Third, identification of a foreign structure without legal personality by its name, registration number, address, place of principal activity and nature of activity and, for trusts, by the assets under management, the settlors and the beneficiaries. Fourth, identification of the beneficial owner from the constituent documents, the shareholder register, the register of beneficial owners of legal entities and other sources; where the customer’s information conflicts with the register and there are sufficient grounds to believe that the legal entity is involved in laundering, terrorist financing or proliferation financing, the SFM must terminate the business relationship or refuse to establish it. Fifth, establishing the intended purpose and nature of the business relationship. Sixth, ongoing monitoring of the relationship and scrutiny of transactions, including, where necessary, the source of funds. Seventh, verification of the data and its updating: once doubts arise, the information is updated within 15 working days after the day the decision that doubts exist is taken. Customers must provide the information requested, including data on beneficial owners, tax residence, type of activity and source of funds (paragraph 5 of Article 5).

Exemptions for one-off transactions (paragraph 3-1 of Article 5). Due diligence is not performed for certain one-off transactions below fixed amounts — in most cases only for individual customers, and provided the transaction is not suspicious.

Tra­nsa­ction

Exemption threshold, KZT

Cash deposit by an individual customer to an indi­vi­dual’s account, or payment for services through a cash-a­cce­ptance device

500,000

Non-cash payment or transfer without opening a bank account

500,000

Purchase, sale or exchange of cash foreign currency by an individual at an exchange office

500,000

Retail purchase of jewellery by an individual

500,000

Purchase of refined gold bars by an individual at an exchange office

500,000

Tra­nsa­ction by an individual with a payment card that is not a means of access to his or her bank account

200,000

Payment of an insurance premium by an individual under an insurance contract

100,000

Payments in enfo­rce­ment pro­cee­dings to state bodies through cash-a­cce­ptance devices; premiums and payouts under compulsory insurance

No threshold

Simplified and enhanced measures (paragraph 7 of Article 5). At a low level of risk the SFM may apply simplified due diligence — update identification data and review the relationship less often, and infer the purpose of the relationship from the nature of the transactions; simplified due diligence is prohibited where there is suspicion or high risk. At a high level of risk, enhanced due diligence applies: establishing the reasons for transactions, increasing the frequency of checks, obtaining information on the customer’s activity and source of funds, and approval by a senior manager. Enhanced due diligence is mandatory for customers from jurisdictions that fail to implement the FATF Recommendations (paragraph 10 of Article 5); reliance on due diligence performed by organisations in such jurisdictions, and outsourcing to them, are prohibited. Any SFM may entrust due diligence to another person, including another SFM, under a contract, but responsibility for compliance remains with the SFM (paragraph 8 of Article 5); reliance on due diligence already performed by another SFM or by a foreign financial institution is open only to financial-sector entities — banks, exchange and clearing organisations, insurers, pension funds, professional securities-market participants, microfinance organisations and payment organisations (sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3) — on condition that the data are obtained immediately and the documents are retained for five years (paragraph 6 of Article 5).

Establishing relationships remotely (paragraph 9 of Article 5). The requirements for remote identification by banks (other than entities carrying out only currency-exchange operations), exchange and clearing organisations (other than commodity exchanges), insurers, pension funds, professional securities-market participants and microfinance organisations are set by the ARDFM in agreement with the AFM; for AIFC participants, by the AFSA. A relationship may not be established remotely with persons on the terrorist-financing and proliferation-financing lists, with persons under UN Security Council sanctions, or with high-risk customers (except electronic insurance through bank accounts). For banks, ARDFM Resolution No. 18 requires biometric authentication through the Identity Data Exchange Centre and retention of the video-session recording for at least five years after the relationship ends.

Politically exposed persons (Article 8; the Law’s term is “public officials”). For foreign politically exposed persons — foreign public officials, persons performing public functions for a foreign state and heads of international organisations — the SFM must additionally: check whether the customer and the beneficial owner are connected to a politically exposed person, his or her spouse and close relatives; assess that person’s reputation; obtain written approval from a senior manager for establishing or continuing the relationship; take available measures to establish the source of funds; and apply enhanced due diligence on an ongoing basis. The same measures apply to Kazakhstan’s own politically exposed persons on the list approved by the President, and to their spouses and close relatives, who have been assigned a high level of risk — and continue to apply for 12 months after the official leaves office (paragraph 4 of Article 8). Since 13 August 2026, Law No. 311-VIII has refined the criterion for heads of international organisations established by states under international treaties.

Author’s assessment: a mismatch with the register of beneficial owners has become a risk for the customer, not only for the SFM. Since the creation of the state register of beneficial owners in 2023, the fourth due-diligence measure has required the customer’s information to be checked against it, and the current wording of sub-paragraph 2-2) of paragraph 3 of Article 5 expressly obliges the SFM to end the relationship where a mismatch coincides with sufficient grounds to suspect involvement in laundering. For a foreign-owned company this means that the data on ultimate owners filed at registration must match what the company tells its bank, its notary and its auditor; how the ownership structure of an LLP is arranged, and how the choice between an LLP and an AIFC participant is made, is examined in AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026.

How the Register of Beneficial Owners Works and What Companies Themselves Must Do

A beneficial owner is an individual who directly or indirectly holds more than 25 % of the participatory interests in the charter capital or of the placed shares of a legal entity, or who otherwise controls the customer, or in whose interest the customer carries out transactions in money and other property (sub-paragraph 3) of Article 1 of Law No. 191-IV). The concept operates in three regimes at once: as the object of an SFM’s due diligence (Article 5), as the content of the state register (Article 6-1) and as the subject of an independent duty of every legal entity (Article 12-3).

The register of beneficial owners of legal entities (Article 6-1, introduced by Law No. 23-VIII of 12 July 2023) is a state database kept by the AFM. It records the legal entity’s name and BIN, its legal form, address and the particulars of its head, and for each beneficial owner — full name, identity-document particulars, date and place of birth, address, citizenship, IIN and the size of the holding. The register is populated through integration with state information systems, from law-enforcement information, on request, from information submitted by legal entities and from SFM findings; access is granted to supervisory state bodies, law-enforcement and special state bodies and SFMs themselves. Under the Rules approved by AFM Order No. 5 of 25 September 2023, the register sits in the closed part of the AFM web portal, is searched by IIN or BIN, and each entry carries a status: registration-based — the beneficial owner was declared at state registration in the “Legal Entities” database — or presumed, computed by the AFM through the ownership chain. An SFM that finds, in the course of due diligence, a discrepancy between the customer’s data and the register reports it through the personal account.

The legal entity’s own duties (Article 12-3, introduced by Law No. 131-VII of 1 July 2022). Every legal entity and every foreign structure without legal personality must: identify its beneficial owners on the form approved by the AFM in agreement with the Ministry of Justice; verify the information; update it at least once a year or on any change; keep it for at least five years; and provide it to the AFM on request. Founders, participants and controlling persons must supply the company with the necessary data. For late provision of the information on an AFM request, part 6 of Article 214 of the CAO provides a warning or a fine of 40 to 400 MCI; for failure to provide it or for false information, part 7 provides 45 to 420 MCI (280 MCI, or KZT 1,211,000, for a medium-sized enterprise). The duty does not extend to state institutions and quasi-public entities.

Author’s assessment: Article 12-3 makes every LLP a participant in the AML system even if it is not an SFM. An ordinary trading company files no reports with the AFM, but it must keep an up-to-date internal beneficial-owner questionnaire, update it annually and answer any AFM request — and when a participatory interest is sold or a controlling person changes, the data must change in the register, in the questionnaire and in the information previously given to the bank. Companies with a holding structure running through the UAE or Hong Kong will find it useful to compare the Kazakhstan standard with the beneficial-ownership disclosure requirements of those jurisdictions, described in The UAE UBO Register and goAML and Kazakhstan + UAE: The Dual Structure in 2026.

How and by When Reports Are Filed with the AFM

A report to the AFM is an electronic document on Form FM-1 that an SFM sends to the authorised body about a transaction subject to financial monitoring, a customer’s suspicious activity, a refusal of service or the freezing of transactions. The procedure is laid down in Article 10 of Law No. 191-IV and in the Rules for Providing Information approved by AFM Order No. 13 of 22 February 2022 (as reworded by Order No. 22 of 23 December 2025, in force since 1 April 2026, with the amendments of Order No. 12 of 16 June 2026, in force since 12 July 2026). Reports are filed in Kazakh or Russian through dedicated channels: the personal account, the external gateway of e-government, API services or the networks of the National Bank’s National Payment Corporation (paragraph 2 of the Rules). Form FM-1 is generated in XML, signed with the electronic digital signature of the responsible officer, and has four sections: form data, SFM data, particulars of the transaction or suspicious activity, and particulars of the participants (paragraphs 3–4 of the Rules). The cost of transmitting information is borne by the SFM (paragraph 4 of Article 10).

Event

Reporting or action deadline

Provision

Threshold tra­nsa­ction (paragraph 1 of Article 4)

No later than the working day following the tra­nsa­ction

Paragraph 2 of Article 10

Suspicious tra­nsa­ction detected before execution

Before the tra­nsa­ction is carried out

Paragraph 2 of Article 13

Tra­nsa­ction recognised as suspicious after execution

No later than 24 hours after reco­gni­tion

Paragraph 2 of Article 13

Customer’s suspicious activity (two or more tra­nsa­ctions)

No later than three working days after the day of reco­gni­tion

Arti­cle­ 10-1

Tra­nsa­ction matching an AFM typology (paragraph 5 of Article 4)

No later than the working day following reco­gni­tion

Paragraph 2 of Article 10

Refusal to establish a rela­tio­nship, termi­na­tion of a rela­tio­nship, refusal of a tra­nsa­ction

No later than the working day following the decision

Paragraph 2 of Article 13

Freezing of tra­nsa­ctions under the lists

No later than the working day following the measures

Paragraph 2 of Article 13

AFM notice of acceptance or rejection of a report

Within four hours

Paragraph 6 of the Rules

Correction of a rejected report

Within 24 hours (excluding weekends and public holidays)

Paragraph 6 of the Rules

Correction of an accepted report on discovery of an error

No later than the next working day

Paragraph 6 of the Rules

AFM decision to suspend or permit a suspicious tra­nsa­ction

Within 24 hours of receipt of the report

Paragraph 3 of Arti­cle­ 13; paragraph 7 of the Rules

Answer to an AFM request for info­rma­tion and documents

Within three working days of receipt; for a request within the analysis of a suspicious tra­nsa­ction — no later than the working day on which the request is received

Paragraph 3-1 of Article 10

Extension of the three-day deadline on the SFM’s written appli­ca­tion (at the AFM’s discre­tion)

By no more than 10 working days

Paragraph 3-1 of Article 10

Answer of a money­-tra­nsfer system operator to a bank’s request

Two working days

Paragraph 3-2 of Article 10

Technical failure of channels or software confirmed by the AFM

The report is deemed timely if filed within one working day after the failure is remedied

Paragraph 8 of the Rules

Who does not report. Advocates, legal consultants and other independent legal specialists do not report information obtained while representing and defending a client before the bodies of inquiry and preliminary investigation and in court, or while providing legal assistance in the form of consultations, explanations, written opinions and the drafting of statements of claim and other legal documents; notaries do not report notarial acts not involving money or property, or consultations (paragraph 3 of Article 10). The exemption does not cover support of real-estate transactions, management of client funds or the creation of companies — the very operations for which lawyers are on the SFM list.

What is not a breach of confidentiality. Filing reports and documents with the AFM is not a disclosure of commercial, banking or other legally protected secrecy and does not breach personal-data legislation (paragraph 6 of Article 11), and an SFM, its employees and its officers bear no liability under law or contract for a report filed in the prescribed manner, whatever its outcome (paragraph 7 of Article 11).

Author’s assessment: the 24-hour window for corrections is the typical point of exposure to a fine under part 12 of Article 214 of the CAO. The Rules provide for rejection of a report with a notice within four hours and re-filing within 24 hours; until the corrected report is accepted, the duty to report the threshold transaction remains unperformed, and because the report itself must go out on the next working day, an SFM without an on-duty responsible officer effectively has no margin of time at all. A company becoming an SFM for the first time is well advised to make a test filing in the personal account before its first real transaction and to set out in its ICR who signs the form when the responsible officer is absent; UPPERSETUP’s accounting support can help set up the internal records and the allocation of roles.

What the Internal Control Rules Must Contain, Who the Responsible Officer Is and How Training Works

Internal control rules (ICR) are the SFM’s internal document which, under paragraph 3 of Article 11 of Law No. 191-IV, is approved by its executive body (or by the entity itself if it has no legal personality) with regard to the results of the risk-exposure assessment of its services and to the size, nature and complexity of its activity, and which must include at least five programmes: a programme for organising internal control, with the appointment of a responsible officer; a risk-management programme with two levels of risk (high and low) that also covers new-technology risks; a customer-identification programme; a programme for monitoring and scrutinising transactions, including complex, unusually large and other unusual transactions; and a training programme. The ICR requirements for the non-financial sector are set by AFM Order No. 4 of 6 August 2021 as reworded by Order No. 15 of 25 November 2025; the ICR are uploaded to the personal account (paragraph 4 of the Requirements). Financial groups may adopt single ICR for the entities in sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3 — banks, exchange and clearing organisations, insurers, pension funds, professional securities-market participants, microfinance organisations and payment organisations.

The responsible officer. Under paragraph 3 of Article 11 the responsible officer is appointed from among senior managers or heads of units not below the head of the relevant structural unit and must have an impeccable business reputation. For the non-financial sector, paragraph 6 of AFM Requirements No. 4 adds: an employment contract with the SFM, direct reporting to the head of the entity, higher or secondary professional education, at least two years’ experience in AML/CFT or in the entity’s field of activity, and a test certificate uploaded to the personal account; an individual entrepreneur or an individual appoints himself or herself, and only the certificate requirement applies. A person standing in for the responsible officer during leave, illness or a business trip must meet the same requirements, and the procedure for such substitution forms part of the programme for organising internal control (paragraphs 5–6 of the Requirements).

Training and testing (AFM Order No. 6 of 9 August 2021 as reworded by Order No. 27 of 29 December 2025). The responsible officer and the staff of the AML/CFT unit sit the test on the AFM website online, under biometric control, before taking up their functions; entities practising alone — within three months of starting activity. The test has 100 questions to be answered in 100 minutes; the pass mark is at least 70 correct answers; a resit is allowed after 14 calendar days; the result is valid for three years; the AFM keeps records of those who have been tested. The training programme covers AML/CFT legislation and the FATF standards, the entity’s ICR, liability under Articles 214 and 214-1 of the CAO, and typologies and indicators; additional training is held when the legislation or the ICR change.

Periodic ICR duties (AFM Requirements No. 4 for the non-financial sector). A review of the internal control system at least once a year by external or internal audit or by an employee not involved in AML/CFT, with a written report (paragraph 7); updating of data on high-risk customers at least once every six months (paragraph 15); risk assessment of new products before launch (paragraph 16); an annual assessment of the exposure of customers and services to risk, with the results uploaded to the personal account by 10 January of the following year (paragraph 17). For banks, ARDFM Resolution No. 18 requires data on high-risk customers to be updated at least once a year and, for certain categories, quarterly. Beyond its own ICR, under Article 11-1 every SFM must document and update its own risk assessment, take account of the national and sectoral assessments, and classify customers by risk level.

Record-keeping and the confidentiality of reports (paragraphs 4 to 5-1 of Article 11). Due-diligence documents, including the customer file, account data and correspondence, are kept for at least five years from the end of the business relationship; documents on transactions, including threshold and suspicious ones, and the results of scrutiny of unusual transactions — for at least five years after the transaction, in a form that allows the transaction, including amounts and currencies, to be reconstructed. An SFM and its employees may not inform customers or other persons of the AML/CFT measures taken — other than telling the customer of a freeze, a refusal to establish a relationship or a refusal of a transaction — or of receipt from the AFM of a list of persons carrying out suspicious transactions; a breach of this prohibition is punishable under part 17 of Article 214 of the CAO by a fine of 75 to 640 MCI with no warning option. Five-year retention of customer files has to be reconciled with personal-data legislation — retention periods, database localisation and the grounds for processing are described in Personal Data and Localisation in Kazakhstan in 2026.

Author’s assessment: the responsible officer is the one position for which the Law requires status, experience and a certificate all at once, and it is the one most often filled as a formality. Appointing an accountant or a lawyer as a secondary appointment without two years’ experience, without uploading the certificate to the personal account and without genuine reporting to the head makes the ICR non-compliant (part 15 of Article 214 CAO — up to 700 MCI), and in an AFM inspection the absence of a certificate is detected automatically from the personal-account data. For businesses whose volume of transactions does not justify a full-time specialist, it is more practical to split the functions: a responsible officer from among the managers on the payroll, with the ICR methodology, the annual internal-control review and test preparation supported externally; UPPERSETUP’s legal support offers that form of assistance.

When an SFM Must Refuse a Customer, Freeze Transactions and Suspend Them on the AFM’s Decision

Refusal, freezing and suspension are three different instruments of Article 13 of Law No. 191-IV with different grounds and deadlines. Refusal is the SFM’s own decision; freezing is the automatic consequence of a person’s inclusion in the lists published by the AFM; suspension is a decision of the AFM or a law-enforcement body on a specific transaction.

Refusal (paragraph 1 of Article 13). An SFM must refuse to establish a business relationship if it is impossible to identify the customer, its representative and its beneficial owner and to establish the purpose of the relationship; it must refuse to carry out a transaction and/or terminate the relationship if it is impossible to take the same measures and to verify the data; and it may refuse or terminate the relationship on suspicion of laundering, terrorist financing or proliferation financing. Refusals and terminations are reported to the AFM no later than the next working day (paragraph 2 of Article 13). Refusal and termination give rise to no civil liability of the SFM under the contract (paragraph 6 of Article 13).

Freezing (Articles 12, 12-1; paragraph 1-1 of Article 13). The AFM maintains and posts on its website the list of organisations and persons connected with the financing of terrorism and extremism and the list of organisations and persons connected with the financing of the proliferation of weapons of mass destruction, and, at the request of a foreign competent authority, a list of persons involved in terrorist activity. Within 24 hours of the list being posted or a person being added to it, the SFM must immediately suspend debit transactions on the bank accounts of that person, of customers whose beneficial owner it is, of organisations under its control and of persons acting on its behalf (except account-servicing operations), suspend the execution of payment instructions given without opening a bank account, block securities, refuse insurance payouts and premium refunds and refuse other transactions — except credits to the account and mandatory pension contributions. Extensions of deposits and debits to repay loans, leases and microcredits under contracts concluded before listing are permitted, as are transactions under a court decision and tax-authority collection orders. An individual listed on domestic grounds (sub-paragraphs 3)–6) of paragraph 4 of Article 12) may receive living expenses — wages up to the minimum wage per family member per month, pensions and benefits — and pay taxes and utilities (paragraph 8 of Article 12). Removal from a list takes place within one working day of the decision.

Measure

Taken by

Deadline

Provision

Freezing of tra­nsa­ctions of listed persons

SFM

Within 24 hours of publi­ca­tion of the list

Paragraph 1-1 of Article 13

Freezing under a list at the request of a foreign competent authority

SFM

Up to 15 ca­le­ndar days

Paragraph 10 of Article 12

Freezing at the request of a foreign financial inte­lli­gence unit

SFM on notice from the AFM

Within 24 hours; for up to 30 ca­le­ndar days

Paragraph 4-1 of Arti­cle­ 19-2

Decision on a suspi­cious-tra­nsaction report

AFM

Within 24 hours of receipt of the report

Paragraph 3 of Article 13

Suspension of a suspicious tra­nsa­ction

AFM

Up to three working days

Paragraph 3 of Arti­cle­ 13; Article 17

Decision of a law-e­nforce­ment or special body after suspension

Law-e­nforce­ment body

Within 72 hours; the AFM relays the decision to the SFM within three hours

Paragraph 5 of Article 13

Suspension of debit tra­nsa­ctions on accounts and e-money on a law-e­nforce­ment decision

AFM

Up to 15 ca­le­ndar days

Paragraph 5-1 of Article 13

Tra­nsa­ctions under contracts concluded before listing on the prolife­ration-fi­nancing list

AFM

Suspension within 24 hours for up to 15 working days; decision within three working days

Paragraph 6 of Arti­cle­ 12-1

Suspension of a suspicious transaction. Having reported a suspicious transaction before executing it, the SFM does not carry it out until the AFM decides; if no decision is received within 24 hours of filing the report, the transaction must be carried out unless other lawful grounds prevent it (paragraph 4 of Article 13). Failure to suspend a transaction on the AFM’s decision is punishable under part 14 of Article 214 of the CAO by a fine of 75 to 600 MCI. State bodies bear no liability for losses, including lost profit, caused by a suspension (paragraph 6 of Article 13).

Author’s assessment: freezing is the only SFM duty whose performance is measured in hours and does not depend on the size of the entity. The lists are updated in the ordinary course of business and the 24-hour period runs from the moment of posting on the AFM website, so the monitoring programme must provide for periodic screening of the entire customer base against the lists, not only a check when the relationship is established; for a jewellery salon or a real-estate agency without an automated system that is a daily manual procedure. Companies receiving payments in Kazakhstan from foreign counterparties should also consider the reverse side: blocking of a transaction under the proliferation-financing list is not a breach of contract by the bank (paragraph 6 of Article 13), so any dispute over the unexecuted payment will have to be pursued against the counterparty, not the bank.

How the AFM and Sector Regulators Supervise Subjects of Financial Monitoring, and What the EAG Assessment Shows

State control in the AML/CFT field is, under Article 14 of Law No. 191-IV, the control that each supervisory body exercises within its own competence: the ARDFM over banks, insurers and professional securities-market participants; the National Bank over exchange offices and payment organisations; the regulators under the digital-assets legislation over digital-asset operators; the Ministry of Justice over notaries; and the AFM directly over legal consultants and independent legal specialists (other than advocates), accounting organisations and professional accountants (other than audit organisations), lessors, jewellers, real-estate agents, the Social Health Insurance Fund, the State Corporation and mobile operators. The AFM uses three forms: unscheduled inspections, preventive control with a visit and preventive control without a visit to the entity.

Preventive control without a visit (Article 14-1, introduced by Law No. 219-VIII). The AFM analyses information from the media and from state information systems — including personal-account data — and, on detecting a breach, issues a compliance notice within 10 working days; the notice is deemed served when handed over against signature, sent by post or courier, or posted in the personal account. The entity must, within the period stated in the notice but not less than 10 working days, submit a letter with supporting materials or a remediation plan; objections may be lodged within 10 working days. Failure to comply with the notice leads to inclusion in the half-yearly list for preventive control with a visit. Separately, supervisory bodies must carry out a sectoral risk assessment once every three years (sub-paragraph 6) of paragraph 1 of Article 18), and SFMs must take its results into account in their own risk assessment (Article 11-1).

Policy documents. Presidential Decree No. 1038 of 6 October 2022 approved the Concept for the Development of Financial Monitoring 2022–2026: according to it, the number of SFMs covered by the AML/CFT system grew from 6,000 to 9,000 over 2019–2021 (2,000 in the financial sector, 7,000 in the non-financial sector), while over the same period entities filed more than 5 million reports, 99 % of them from the financial sector; the target indicators for 2026 are 90 % of SFMs registered in the AFM information system and 35 “compliant” or “largely compliant” ratings on the FATF Recommendations. Government Resolution No. 934 of 7 November 2025 approved 44 measures with deadlines running to December 2027, on which the AFM reports to the Government twice a year.

Results for 2025. According to the AFM Chairman’s report to the President on 12 January 2026, in 2025 the investigation of 1,135 criminal cases was completed, KZT 141.5 billion was recovered for victims, 15 criminal groups and 29 cash-out platforms with a turnover of over KZT 128 billion were dismantled, 22 shadow crypto-exchangers were shut down, more than 1,100 illegal online crypto-exchange services and 20,000 drop cards were blocked; the financial sector terminated business relationships with 2,000 companies and 56,000 individuals on suspicion of laundering, and criminal online-casino flows of KZT 2.1 trillion passed with the complicity of 35 payment organisations.

International assessment. Kazakhstan is a co-founder of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), a FATF-style regional body. The third-round mutual evaluation report was adopted at the 38th EAG Plenary on 8 June 2023, and the country was placed in regular follow-up. The first follow-up report with re-ratings was adopted by the EAG Plenary in May 2026 and published on 29 June 2026: the ratings on Recommendations 6, 7, 24 and 26 were upgraded from “partially compliant” to “largely compliant”, while Recommendation 28 — on the regulation and supervision of non-financial SFMs — remained “partially compliant”; as a result, Kazakhstan is rated “compliant” or “largely compliant” on 37 of the 40 FATF Recommendations and remains in regular follow-up. Kazakhstan does not appear on the FATF list of jurisdictions under increased monitoring of 19 June 2026 (22 jurisdictions).

Author’s assessment: the retained “partially compliant” rating on Recommendation 28 sets the AFM’s focus for 2026–2027. Recommendation 28 concerns the supervision of notaries, lawyers, accountants, real-estate agents, jewellers and gambling operators — precisely the entities the AFM supervises directly; the logical regulatory response is a rise in the number of compliance notices under Article 14-1 and of inspections in the non-financial sector, where, according to the Concept’s figures for 2019–2021, 7,000 of the 9,000 entities were concentrated but only 1 % of reports originated. For businesses in that sector the current year is the last opportunity to put the ICR, the personal account and the certificates in order before preventive control becomes systematic; Kazakhstan’s model of non-financial-sector supervision can be compared with the Emirati and Hong Kong models in DNFBP AML Compliance in the UAE 2026 and The Hong Kong TCSP Licence in 2026.

What Liability Attaches to a Breach of the Duties of a Subject of Financial Monitoring

The liability of an SFM is built on three levels: administrative liability under Article 214 of the Code of Administrative Offences for breach of the duties themselves; administrative liability of a legal entity under Article 214-1 of the CAO for a transaction in property known to be the proceeds of crime; and criminal liability of individuals under Article 218 of the Criminal Code for laundering. Article 214 of the CAO applies in the wording of Law No. 247-VIII of 30 December 2025, in force since 2 March 2026, and contains 19 parts with four fine scales: for individuals; for officials, notaries and advocates, small-business entities and non-profit organisations; for medium-sized business entities; and for large-business entities and branches of non-resident banks, insurers and insurance brokers. The monthly calculation index (MCI) for 2026 is KZT 4,325 (sub-paragraph 4) of Article 7 of Law No. 239-VIII of 8 December 2025 “On the Republican Budget for 2026–2028”).

Part of Arti­cle­ 214 CAO

Breach

Indi­vi­duals

Officials, notaries, advocates, small business, NPOs

Medium business

Large business, branches of non-re­si­dents

1

Breach of the rules on recording, storing and protecting info­rma­tion and documents

30

70

210

280

2

Late report of a suspicious tra­nsa­ction or a tra­nsa­ction matching a typology

Warning or 65

180

290

520

3

Failure to report, or knowingly false report of, a suspicious tra­nsa­ction

75

210

330

600

4

Late answer to an AFM request

Warning or 40

110

280

420

5

Failure to answer, or false info­rma­tion in answer to, an AFM request

45

120

300

450

6

Late submission of bene­ficia­l-owner info­rma­tion on request (paragraph 5 of Arti­cle­ 12-3)

Warning or 40

100

250

400

7

Failure to submit, or false, bene­ficia­l-owner info­rma­tion on request

45

110

280

420

8

Failure to take due­-dili­gence measures

40

110

280

420

9

Breach of the freezing duties and of reporting of freezing

75

195

330

600

10

Failure to refuse a customer or to report the refusal

40

110

280

420

11

Failure to implement the training programme

30

70

210

280

12

Late report of a threshold tra­nsa­ction

Warning or 40

100

260

400

13

Failure to report, or false report of, a threshold tra­nsa­ction

45

120

300

450

14

Failure to suspend a tra­nsa­ction on the AFM’s decision

75

210

330

600

15

ICR not compliant with the legi­sla­tion

Warning or 110

180

320

700

16

Failure to develop and adopt ICR

120

195

345

750

17

Tipping off customers and other persons about AML/CFT measures

75

210

330

640

18

Repeat breach within a year under parts 1, 3, 5, 7–11, 13, 14, 16, 17

150

225

375

900

19

Breach under parts 1–17 three or more times within a year

200

450

900

1,800

All amounts are in MCI. For a medium-sized enterprise the fine under part 3 is 330 MCI, or KZT 1,427,250; under part 16, 345 MCI, or KZT 1,492,125; under part 19, 900 MCI, or KZT 3,892,500; for large business and branches of non-resident banks, part 19 means 1,800 MCI, or KZT 7,785,000. Part 19 additionally entails suspension of the licence or qualification certificate for up to six months or their revocation, suspension of activity for up to three months, or a ban on the activity or certain of its types for up to three years. A warning instead of a fine is available only under parts 2, 4, 6, 12 and 15 — for late reports and answers and for non-compliant ICR, never for a failure to report.

Related offences. Article 214-1 of the CAO punishes a legal entity that carries out a transaction in money or property known to it to have been obtained by crime, where this results in laundering: 750 MCI for small-business entities and non-profit organisations, 1,000 MCI for medium-sized and 2,000 MCI (KZT 8,650,000) for large-business entities; voluntary disclosure of such a transaction exempts from liability. Article 463 of the CAO punishes activity without a mandatory notification with a fine of 15 to 150 MCI (40 MCI for a medium-sized enterprise) and, for a repeat offence, 30 to 500 MCI. Article 218 of the Criminal Code provides, for the laundering of proceeds of crime, a fine of up to 5,000 MCI or restriction or deprivation of liberty for up to six years with confiscation of property; where committed by a group, repeatedly or with the use of an official position — a fine of 3,000 to 7,000 MCI or imprisonment for three to seven years; and where committed on a large scale, by a criminal group or by an official using his or her position — imprisonment for five to ten years with confiscation; a person who voluntarily reports a planned or completed laundering is exempt from criminal liability unless his or her acts contain the elements of parts 2 or 3 of that Article or of another offence.

Author’s assessment: the economics of the fines have made inaction more expensive than compliance for any medium-sized enterprise. The simultaneous absence of ICR (part 16), failure to take due-diligence measures (part 8) and failure to report threshold transactions (part 13) — the typical set for a company unaware of its status — adds up to 925 MCI, or KZT 4,000,625, before any repeat; a repeat within a year moves each of those breaches into part 18 (375 MCI), and a third into part 19 with the risk of suspension of activity. A separate exposure is the head’s liability as an official on the second scale and the criminal risk under Article 218 where intent is proved; how that risk interacts with a director’s duties when the company is insolvent is described in Bankruptcy and Rehabilitation of Legal Entities in Kazakhstan in 2026.

Step-by-Step Algorithm: What a Company Becoming a Subject of Financial Monitoring Should Do

The algorithm for launching an internal control system is a sequence of twelve steps that takes a company from “we did not know we were an SFM” to readiness for AFM preventive control. The order matters: the responsible officer’s test precedes adoption of the ICR, registration in the personal account precedes the first report, and the notification of commencement precedes everything else.

Step 1. Determine the status. Match the actual activity against the sub-paragraphs of paragraph 1 of Article 3 of Law No. 191-IV: for legal consultants the status arises only when they take part in five kinds of transactions on a client’s behalf, for accounting organisations — when they carry on accounting as a business, for real-estate agents — when they act as intermediaries in sales and purchases of real estate. Record the conclusion in writing with the sub-paragraph cited.

Step 2. File the notification of commencement of activity. For legal consultants and independent specialists, unlicensed lessors, dealers in precious metals and jewellery and real-estate agents — through the elicense.kz portal under item 35 of Annex 3 to Law No. 202-V, before starting activity; keep the receipt. Advocates, notaries, accountants and licensed entities do not file it.

Step 3. Appoint the responsible officer. By order of the head — from among senior managers or heads of units with an impeccable business reputation; for the non-financial sector, check the two years’ experience and the education required by paragraph 6 of AFM Requirements No. 4. An individual entrepreneur appoints himself or herself.

Step 4. Pass the test. The responsible officer and the staff of the AML/CFT unit sit the online test on the AFM website under biometric control before taking up their functions (100 questions, 100 minutes, at least 70 correct answers); sole practitioners — within three months. The certificate is valid for three years.

Step 5. Carry out a risk assessment. Document the entity’s own assessment of laundering, terrorist-financing and proliferation-financing risks under Article 11-1, taking into account the national and sectoral assessments, the AFM typologies and the FATF list; define the risk categories (country, customer, product, channel) and the two customer risk levels.

Step 6. Adopt the ICR. Draft the programmes — at least five — required by paragraph 3 of Article 11 and by the sector requirements (AFM Order No. 4 for the non-financial sector, ARDFM Resolution No. 18 for banks, Ministry of Justice Order No. 705 for notaries), have them approved by the executive body, and specify in the monitoring programme the frequency of transaction review — it determines the permissible interval between execution of a transaction and its recognition as suspicious.

Step 7. Register in the personal account. Enter the BIN or IIN on the AFM portal; if the type of activity does not match, send the documents within three working days; after authorisation, complete the organisation’s data and the data of the responsible persons and sign with the electronic digital signature. Upload the ICR, the risk-assessment results and the certificate.

Step 8. Set up due diligence. Introduce customer and beneficial-owner questionnaires, a check against the register of beneficial owners, screening against the terrorist-financing and proliferation-financing lists, the list of politically exposed persons and the FATF country list; set out the procedure for updating data within 15 working days once doubts arise and at least once every six months for high-risk customers.

Step 9. Set up detection of threshold transactions. Extract from paragraph 1 of Article 4 the items relevant to the entity’s activity: a real-estate agent watches the KZT 50,000,000 threshold on real-estate deals, a jeweller KZT 5,000,000, a lessor KZT 45,000,000, a notary the thresholds on the transactions in money and property that he or she certifies (real estate, movable property, gratuitous transfers of money). Make a test filing of Form FM-1 through the personal account.

Step 10. Set up monitoring of suspicious transactions. Implement the four grounds for mandatory scrutiny under paragraph 4 of Article 4 and codes 11–27 of Annex 2 to AFM Order No. 13; specify who takes the decision to treat a transaction as suspicious, within what time, and how the date and grounds are recorded; provide for counting two or more suspicious transactions of one customer so that suspicious activity is reported within three working days.

Step 11. Organise the daily and periodic procedures. Daily — screening against the AFM lists for freezing within 24 hours; on every report — checking the AFM notice within four hours and correcting within 24 hours; annually — the review of the internal control system and the risk-exposure assessment uploaded by 10 January; on any change in the legislation — additional training.

Step 12. Ensure record-keeping and information security. Organise five-year retention of customer files and transaction documents in a form that allows amounts and currencies to be reconstructed; limit the number of people who know that reports have been filed; record in the ICR the prohibition on tipping off customers and the procedure for telling a customer of a refusal or a freeze.

Author’s assessment: three steps cannot be left “for later”. The first is the notification of commencement of activity: without it, the activity itself is an offence under Article 463 of the CAO. The second is the responsible officer’s test: without the certificate, the ICR are non-compliant from day one. The third is registration in the personal account: without it, the entity can neither file a report nor receive an AFM compliance notice, and a notice under Article 14-1 posted in the account is deemed served whether or not the entity has logged in. For a foreign group that is simultaneously registering an LLP, opening an account and registering for tax, these steps fit naturally into a single launch plan; the ready-made UPPERSETUP company registration platform can serve as the starting point for such a plan.

Typical Mistakes of Subjects of Financial Monitoring and What They Cost

The typical mistakes of SFMs are recurring breaches, each with a specific price in Article 214 of the CAO. Below are eight mistakes with an estimate of their cost for a medium-sized enterprise at the MCI of KZT 4,325.

Mistake 1. The company does not know it is an SFM. An accounting firm, a law firm supporting real-estate deals and LLP registrations, a real-estate agency or a jewellery shop operates without a notification, without ICR and without reports. Cost: Article 463 CAO — 40 MCI (KZT 173,000); part 16 of Article 214 — 345 MCI (KZT 1,492,125); part 8 — 280 MCI (KZT 1,211,000); part 13 for each missed threshold transaction — 300 MCI (KZT 1,297,500). In total, from KZT 4,173,625 on the first detection.

Mistake 2. The ICR are copied from someone else’s template and not uploaded to the personal account. The programmes ignore the entity’s own risk assessment, contain no review frequency for transactions and have not been updated for Law No. 219-VIII and the indicators of Order No. 13 in force since 1 April 2026. Cost: part 15 of Article 214 — a warning or 320 MCI (KZT 1,384,000); if detected in preventive control without a visit — a compliance notice with a period of not less than 10 working days and, if the notice is not complied with, inclusion in the list for control with a visit.

Mistake 3. A responsible officer without a certificate or without the required status. The functions are assigned to an accountant with no experience and no test, and no certificate is uploaded. Cost: part 11 of Article 214 — 210 MCI (KZT 908,250) for failure to implement the training programme, and part 15 — up to 320 MCI for non-compliant ICR; moreover, under AFM Order No. 6 the responsible officer may not take up the AML/CFT functions until the test has been passed.

Mistake 4. Threshold transactions are tracked by the fee rather than by the transaction amount. A real-estate agent reports only deals where the commission is large, a notary only cash settlements, although the KZT 50,000,000 real-estate threshold applies to the price of the property whatever the form of settlement. Cost: part 12 of Article 214 — a warning or 260 MCI (KZT 1,124,500) for a late report; part 13 — 300 MCI (KZT 1,297,500) for a failure to report; a repeat within a year — part 18, 375 MCI (KZT 1,621,875).

Mistake 5. A suspicious-transaction report is filed after execution without observing the 24 hours. The transaction is recognised as suspicious at a monthly review although the ICR set no review frequency, and the report goes out a week later. Cost: part 2 of Article 214 — a warning or 290 MCI (KZT 1,254,250); if treated as a failure to report — part 3, 330 MCI (KZT 1,427,250).

Mistake 6. The customer base is not screened against the lists daily. The terrorist-financing and extremism list has been updated, but a listed customer’s transactions continue on the third day. Cost: part 9 of Article 214 — 330 MCI (KZT 1,427,250) with no warning option; on repeat — 375 MCI.

Mistake 7. The customer is told the reason for a refusal by reference to a report to the AFM. An employee tells the customer that the transaction “has gone to financial monitoring for checking” or forwards an AFM request. Cost: part 17 of Article 214 — 330 MCI (KZT 1,427,250); the Law allows the customer to be told only the bare fact of a refusal, a termination or a freeze.

Mistake 8. An AFM request goes unanswered because the responsible officer is on leave. The request arrives through the personal account, the three-day deadline is missed, no extension is sought, and no stand-in — which paragraph 5 of AFM Requirements No. 4 requires the ICR to provide for during leave — has been appointed. Cost: part 4 of Article 214 — a warning or 280 MCI (KZT 1,211,000); if nothing is provided — part 5, 300 MCI (KZT 1,297,500). A written application for an extension, filed in time, generally removes the risk: the AFM may extend the three-day deadline by up to 10 working days.

Author’s assessment: seven of the eight mistakes are organisational, not legal. They arise not from the complexity of the Law but from the AML/CFT function not being embedded in the daily operating cycle: no calendar of deadlines, no deputy for the responsible officer, no mapping of thresholds to the company’s products. That is why the first AFM inspection usually finds several offences at once, and the aggregate fine for a medium-sized enterprise exceeds KZT 4,000,000 before any repeat is counted. Companies that already outsource their statutory audit and annual reporting can sensibly add the annual AML/CFT internal-control review to the same arrangement; the audit and reporting deadlines are described in Mandatory Audit and Financial Reporting in Kazakhstan in 2026.

For Whom SFM Status Creates the Heaviest Burden and How to Distribute It

The AML/CFT burden is distributed unevenly across the categories of SFM: the Law is the same for all, but the volume of transactions, the presence of a sector regulator and the degree of automation determine what compliance costs. Below are four typical profiles.

Banks, insurers and professional securities-market participants. For them the ICR requirements are set by the ARDFM and the National Bank, the same regulators supervise them, and reports are generated by automated systems; the burden lies in constantly updating those systems for new indicators and typologies, in remote identification and in correspondent relationships (Article 9). According to the Concept for the Development of Financial Monitoring, over 2019–2021 the financial sector filed 99 % of all reports to the AFM, and it is the sector at which the measures of Government Resolution No. 934 on “drops” and cash-outs are aimed.

Notaries, legal consultants, accounting and audit firms. Status arises from the professional activity itself; notaries work under the supervision of the Ministry of Justice pursuant to Order No. 705, lawyers and accountants under the direct supervision of the AFM pursuant to Order No. 4 and its preventive control without a visit. The burden lies in manually detecting threshold deals in real estate, participatory interests and property, in checking against the register of beneficial owners, and in the prohibition on tipping off, which runs against the professional habit of explaining every step to the client. This is the profile with the highest risk at the first inspection.

Real-estate agents, jewellers, unlicensed lessors. Here the notification of commencement of activity is added, and the thresholds — KZT 50,000,000 for real estate, KZT 5,000,000 for jewellery, KZT 45,000,000 for leasing — are triggered regularly; pawnshops, which are on the list as organisations carrying on microfinance activity (sub-paragraph 11)) with a KZT 3,000,000 threshold under sub-paragraph 1-1) of paragraph 1 of Article 4, have a similar profile. It is for this sector that the AFM, under Resolution No. 934, is preparing methodological guidance on tracking market prices of real estate and on comparing customers’ income with their spending on jewellery and precious items, and the retained “partially compliant” rating on FATF Recommendation 28 means tighter supervision.

Digital-asset operators and issuers. Since 1 May 2026 five categories of operators have been SFMs; the ICR requirements for them are set by the National Bank and the ARDFM, the thresholds for transactions in unsecured digital assets are KZT 5,000,000 and for digital financial assets KZT 7,000,000 and KZT 45,000,000, and on AFM request clients’ IP addresses and device and wallet data must be provided (Annex 7 to the Rules approved by Order No. 13). For this sector the key exposure is indicator code 16 and the forthcoming register of high-risk crypto-wallets.

How to distribute the burden. The Law allows three routes, but not all of them are open to every SFM: entrusting due diligence to another person under a contract, with responsibility remaining with the SFM (paragraph 8 of Article 5), is available to all; reliance on due diligence performed by another SFM or a foreign financial institution (paragraph 6 of Article 5) and single ICR for a financial group (paragraph 3 of Article 11) are available only to financial-sector entities under sub-paragraphs 1)–5), 11) and 12) of paragraph 1 of Article 3. The role of responsible officer, approval of the ICR and signature of Form FM-1 cannot be outsourced — these are functions of the entity itself. A practical model for a medium-sized non-financial SFM is a responsible officer from among the managers on the payroll, holding the certificate; external methodological support for the ICR and the annual review; and in-house daily screening against the lists. Foreign-owned companies for which Kazakhstan is one of several jurisdictions can build a single customer- and beneficial-owner verification standard for all the countries where they operate: the UPPERSETUP team supports such companies through its Kazakhstan company management practice — from incorporation and tax registration to the organisation of internal control.

Author’s assessment: SFM status is no reason to abandon a line of business, but it is a reason to price the cost of compliance in advance. For a real-estate agency or a law firm the annual cost of compliance is the responsible officer’s time, the annual internal-control review and the updating of the ICR; by comparison, a single first breach under three typical offences costs a medium-sized enterprise more than KZT 4,000,000. The economically sound choice in 2026 is to embed the AML/CFT function before the first threshold transaction, not after the first compliance notice.

FAQ: Obligations of Subjects of Financial Monitoring in Kazakhstan in 2026

Who is a subject of financial monitoring in Kazakhstan?

Subjects of financial monitoring are listed in paragraph 1 of Article 3 of Law No. 191-IV: banks and organisations carrying out certain banking operations, exchanges and clearing organisations, insurers, pension funds, professional securities-market participants, notaries, advocates and legal consultants when supporting certain transactions, accounting and audit organisations, gambling operators, postal money-transfer operators, microfinance organisations, payment organisations, unlicensed lessors, dealers in precious metals and jewellery, real-estate agents, the Social Health Insurance Fund, AIFC participants, the State Corporation, mobile operators and, since 1 May 2026, five categories of digital-asset operators and issuers. State bodies are not SFMs.

Must an accounting company or a law firm report to the AFM?

Yes, if it falls within sub-paragraphs 7) or 8) of paragraph 1 of Article 3. Accounting organisations and professional accountants in private practice, as well as audit organisations, are SFMs by virtue of their activity; legal consultants and other independent specialists are SFMs only when they act for a client in real-estate transactions, the management of money, securities and accounts, the accumulation of funds for companies, and the creation, purchase, sale and management of legal entities. Information obtained while representing a client in court or before investigative bodies, or while advising, is not reported (paragraph 3 of Article 10).

What transaction amounts are subject to financial monitoring in Kazakhstan?

The thresholds of paragraph 1 of Article 4 of Law No. 191-IV in 2026: KZT 1,000,000 — winnings and cultural valuables; 3,000,000 — pawnshop transactions; 5,000,000 — jewellery, offshore counterparties, anonymous accounts, digital assets; 7,000,000 — gratuitous transfers, shares and units; 10,000,000 — currency exchange, cash transactions on accounts, transactions of companies less than three months old; 45,000,000 — leasing, bonds; 50,000,000 — real estate, movable property, precious metals, loans under National Fund programmes; 100,000,000 in equivalent — cross-border transfers in foreign currency; 500,000,000 — commodity-exchange transactions. Suspicious transactions are reported with no threshold.

By when must a threshold or suspicious transaction be reported to the AFM?

A threshold transaction — no later than the working day following the day it is carried out (paragraph 2 of Article 10). A suspicious transaction — before it is carried out, or, if it is recognised as suspicious afterwards, within 24 hours of recognition (paragraph 2 of Article 13). A customer’s suspicious activity (two or more suspicious transactions) — no later than three working days (Article 10-1). A refusal of a customer and a freeze — no later than the next working day; an answer to an AFM request — within three working days, and for a request within the analysis of a suspicious transaction — no later than the working day on which it is received. The AFM confirms acceptance of a report within four hours; a rejected report is corrected within 24 hours.

What is the personal account of a subject of financial monitoring, and is registration mandatory?

The personal account is the SFM’s profile on the AFM portal, through which reports on Form FM-1 and documents in answer to requests are filed, and to which the ICR, the risk-assessment results and the test certificate are uploaded (sub-paragraph 3-4) of Article 1; paragraph 2-1 of Article 10). Registration is mandatory for all SFMs whether or not they have reportable transactions; the procedure is set by AFM Order No. 18 of 8 December 2025. Registration is by IIN or BIN with an automatic check of the type of activity; on a mismatch, documents are sent within three working days and the AFM decides within the same period.

Who may be the AML/CFT responsible officer, and is a certificate required?

Under paragraph 3 of Article 11 the responsible officer is appointed from among senior managers or heads of units not below the head of a structural unit and must have an impeccable business reputation. For the non-financial sector, AFM Order No. 4 also requires an employment contract, reporting to the head, professional education and at least two years’ experience. The certificate is mandatory: the test is taken on the AFM website under biometric control before taking up the function (sole practitioners — within three months), consists of 100 questions in 100 minutes with a pass mark of at least 70; the result is valid for three years, and the test may be retaken after 14 calendar days.

How long must due-diligence and transaction records be kept?

At least five years: due-diligence documents, including the customer file, account data and correspondence — from the end of the business relationship; transaction documents, including threshold and suspicious transactions, and the results of scrutiny of unusual transactions — after the transaction (paragraph 4 of Article 11). Records must allow the transaction, including amounts and currencies, to be reconstructed. A breach of the record-keeping rules is punishable under part 1 of Article 214 of the CAO by a fine of 30 to 280 MCI.

May a customer be told that a transaction has been reported to the AFM?

No. Paragraph 5 of Article 11 prohibits informing customers and other persons of the AML/CFT measures taken and of reports filed; the customer may be told only of a freeze, a refusal to establish a relationship and a refusal of a transaction. Receipt from the AFM of a list of persons carrying out suspicious transactions may not be disclosed either (paragraph 5-1). A breach is punishable under part 17 of Article 214 of the CAO by a fine of 75 to 640 MCI.

What is the fine for breaching the financial-monitoring law in 2026?

Article 214 of the CAO, in the wording in force since 2 March 2026, contains 19 offences. For a medium-sized enterprise: no ICR — 345 MCI (KZT 1,492,125); failure to take due-diligence measures — 280 MCI; failure to report a threshold transaction — 300 MCI; failure to report a suspicious transaction — 330 MCI; breach of freezing — 330 MCI; tipping off a customer — 330 MCI; a repeat within a year — 375 MCI; three or more breaches — 900 MCI with suspension of the licence for up to six months or a ban on activity for up to three years. For large business the maximum fine is 1,800 MCI (KZT 7,785,000). The 2026 MCI is KZT 4,325.

What changed in the AML/CFT law in 2025–2026?

Law No. 219-VIII of 19 September 2025 (in force since 20 November 2025) renamed the Law, introduced reporting of a customer’s suspicious activity (Article 10-1) and AFM preventive control without a visit (Article 14-1), and rewrote Article 11-1 on risk assessment. AFM Order No. 13 has contained updated suspicion indicators with codes 11–27 since 1 April 2026. Law No. 259-VIII of 16 January 2026 added digital-asset operators and issuers to the SFM list from 1 May 2026. Article 214 of the CAO has applied in its new wording since 2 March 2026. Law No. 311-VIII of 12 June 2026 refined the politically exposed person criterion from 13 August 2026.

Must an ordinary LLP that is not an SFM identify its own beneficial owners?

Yes. Under Article 12-3 of Law No. 191-IV every legal entity and foreign structure without legal personality must identify its beneficial owners on the AFM form, verify and update the information at least once a year, keep it for five years and provide it to the AFM on request; founders and controlling persons must supply the company with the data. Failure to provide the information on request is punishable under part 7 of Article 214 of the CAO by a fine of 45 to 420 MCI.

Is Kazakhstan on the FATF “grey list”?

No. Kazakhstan is not on the FATF list of jurisdictions under increased monitoring of 19 June 2026 (22 jurisdictions). Kazakhstan is assessed within the Eurasian Group (EAG): the third-round report was adopted on 8 June 2023, and the first follow-up report, adopted in May 2026, upgraded the ratings on Recommendations 6, 7, 24 and 26; the country is rated “compliant” or “largely compliant” on 37 of the 40 Recommendations and remains in regular follow-up.

Key Takeaways

First. SFM status arises automatically from carrying on an activity on the 27-item list in paragraph 1 of Article 3 of Law No. 191-IV, including notaries, legal consultants, accounting and audit firms, real-estate agents, jewellers, lessors and, since 1 May 2026, digital-asset operators and issuers; legal consultants (but not advocates), lessors, jewellers and real-estate agents additionally file a notification of commencement of activity under Law No. 202-V.

Second. Kazakhstan’s regime is dual-track: reports are required both for threshold transactions at fixed amounts from KZT 1,000,000 to KZT 500,000,000 (no later than the next working day) and for suspicious transactions with no threshold (before execution or within 24 hours of recognition), and, since 20 November 2025, for a customer’s suspicious activity of two or more transactions (three working days).

Third. Due diligence under Article 5 comprises seven measures — from identification by IIN and BIN to ongoing monitoring — with a mandatory check of the beneficial owner against the state register, updating of data within 15 working days once doubts arise, enhanced due diligence for politically exposed persons and customers from FATF-listed jurisdictions, and exemptions for one-off transactions of up to KZT 500,000.

Fourth. Internal control rests on ICR made up of at least five programmes, a responsible officer at the level of head of unit, holding an AFM certificate (a 100-question test, valid for three years), an annual review of the control system and a risk assessment uploaded to the personal account by 10 January; registration in the personal account is mandatory for every SFM.

Fifth. Transactions of persons on the AFM lists are frozen within 24 hours, the AFM’s decision on a suspicious transaction is taken within 24 hours with suspension for up to three working days, law-enforcement bodies decide within 72 hours, and debit transactions may be suspended for up to 15 calendar days; refusal of a customer where due diligence is impossible is mandatory, and the confidentiality of reports is protected by the prohibition on tipping off.

Sixth. Article 214 of the CAO, in the wording in force since 2 March 2026, contains 19 offences with fines from 30 to 1,800 MCI (KZT 129,750 to KZT 7,785,000 at the MCI of KZT 4,325), with suspension of the licence or a ban on activity for up to three years for a third breach within a year; a legal entity is liable under Article 214-1 for up to 2,000 MCI, and individuals under Article 218 of the Criminal Code for up to 10 years’ imprisonment with confiscation.

Seventh. Supervision is shifting to the non-financial sector: the AFM has acquired preventive control without a visit (Article 14-1), Kazakhstan’s rating on FATF Recommendation 28 on the supervision of non-financial entities remained “partially compliant” in the EAG report of May 2026, and Government Resolution No. 934 provides for new suspicion indicators and methodological guidance for real-estate agents and jewellers during 2026.

Sammary

A subject of financial monitoring in Kazakhstan is a person on the list in paragraph 1 of Article 3 of Law No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction”: banks, insurers, professional securities-market participants, notaries, advocates and legal consultants when supporting transactions, accounting and audit firms, gambling operators, microfinance and payment organisations, unlicensed lessors, jewellers, real-estate agents, mobile operators, AIFC participants and, since 1 May 2026, digital-asset operators and issuers. The duties are: to register in the AFM personal account (and, for legal consultants, lessors, jewellers and real-estate agents, to file a notification of commencement of activity); to conduct due diligence on customers and beneficial owners, updating the data within 15 working days once doubts arise; to report threshold transactions from KZT 1,000,000 to KZT 500,000,000 no later than the next working day, suspicious transactions before execution or within 24 hours of recognition, and suspicious activity within three working days, on Form FM-1; to adopt internal control rules made up of at least five programmes, appoint a responsible officer holding an AFM certificate (a 100-question test, valid for three years), and review the control system and assess risks annually; to freeze transactions of listed persons within 24 hours; to refuse customers where due diligence is impossible; and to keep records for five years without tipping off customers. Liability: Article 214 of the Code of Administrative Offences (since 2 March 2026) — 19 offences with fines from 30 to 1,800 MCI (the 2026 MCI is KZT 4,325), and for a third breach within a year suspension of the licence for up to six months or a ban on activity for up to three years; Article 214-1 — up to 2,000 MCI for legal entities; Article 218 of the Criminal Code — up to 10 years’ imprisonment. Key changes: Law No. 219-VIII (since 20 November 2025) introduced suspicious activity and AFM preventive control without a visit; AFM Order No. 13 updated the suspicion indicators (codes 11–27) from 1 April 2026; Law No. 259-VIII added digital-asset operators from 1 May 2026. Kazakhstan is not on the FATF increased-monitoring list of June 2026 and is rated “compliant” or “largely compliant” on 37 of the 40 Recommendations in the EAG report of May 2026.

Sources

Laws and codes of the Republic of Kazakhstan (Adilet legal information system, consolidated texts)

1.        Law of the Republic of Kazakhstan No. 191-IV of 28 August 2009 “On Counteracting the Legalisation (Laundering) of Proceeds of Crime, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction” — consolidated text (last modified 12 July 2026; incorporating Law No. 311-VIII, in force since 13 August 2026)

2.        Law No. 219-VIII of 19 September 2025 — amendments on AML/CFT/CPF

3.        Law No. 259-VIII of 16 January 2026 — amendments on the financial market, communications and bankruptcy (digital-asset operators on the SFM list)

4.        Law No. 256-VIII of 9 January 2026 — amendments on digitalisation, transport and entrepreneurship

5.        Law No. 311-VIII of 12 June 2026 — amendments on combating corruption

6.        Law No. 113-VIII of 5 July 2024 — decriminalisation of economic offences and improvement of AML/CFT legislation

7.        Law No. 23-VIII of 12 July 2023 — return of illegally acquired assets to the state

8.        Law No. 131-VII of 1 July 2022 — amendments on AML/CFT and state price regulation

9.        Law No. 73-VII of 18 November 2021 — amendments on AML/CFT

10.    Law No. 325-VI of 13 May 2020 — amendments on AML/CFT

11.    Code of Administrative Offences No. 235-V of 5 July 2014 — Articles 214, 214-1, 463

12.    Law No. 247-VIII of 30 December 2025 — amendments to the Code of Administrative Offences (new wording of Article 214)

13.    Criminal Code No. 226-V of 3 July 2014 — Articles 218, 218-1

14.    Law No. 202-V of 16 May 2014 “On Permits and Notifications” — Annex 3, item 35

15.    Law No. 239-VIII of 8 December 2025 “On the Republican Budget for 2026–2028” — sub-paragraph 4) of Article 7 (MCI KZT 4,325)

16.    Law No. 191-IV as amended as at 13 August 2026, with commencement notes on amendments — Paragraph information system

AFM orders and acts of sector regulators

17.    AFM Chairman’s Order No. 13 of 22 February 2022 — Rules for Providing Information on transactions and suspicious activity, and indicators of suspicious transactions (Annex 2)

18.    AFM Chairman’s Order No. 4 of 6 August 2021 — Requirements for internal control rules for the non-financial sector

19.    AFM Chairman’s Order No. 6 of 9 August 2021 — Requirements for subjects of financial monitoring on training and education

20.    AFM Order No. 18 of 8 December 2025 — Rules for the Personal Account

21.    AFM Chairman’s Order No. 5 of 25 September 2023 — Rules for the register of beneficial owners of legal entities

22.    Resolution of the Board of the ARDFM No. 18 of 22 March 2020 — ICR requirements for second-tier banks, branches of non-resident banks and the National Postal Operator

23.    Order of the Minister of Justice No. 705 of 28 November 2025 — ICR requirements for notaries

24.    Order of the Acting Minister of Tourism and Sport No. 250 of 19 December 2025 — ICR requirements for gambling and lottery operators

25.    Order of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development No. 192/НҚ of 8 April 2026 — ICR requirements for postal operators

26.    Resolution of the Board of the ARDFM No. 8 of 24 February 2020 — List of offshore zones for banking and insurance purposes

27.    Order of the Acting Minister of Finance No. 52 of 10 February 2010 — List of offshore zones for the purposes of the AML/CFT Law (repealed with effect from 15 November 2020)

Acts of the President and the Government, official statements

28.    Presidential Decree No. 1038 of 6 October 2022 approving the Concept for the Development of Financial Monitoring 2022–2026

29.    Government Resolution No. 934 of 7 November 2025 approving measures to reduce the risks of laundering

30.    Akorda.kz — Kassym-Jomart Tokayev received AFM Chairman Zhanat Elimanov, 12 January 2026 (results for 2025)

31.    AFSA — Relevance of amendments to Kazakhstan’s AML/CTF law to AIFC Participants (2020 amendments)

FATF and EAG

32.    FATF — Jurisdictions under Increased Monitoring, 19 June 2026

33.    EAG — On publication of the 1st Follow-up Report of the Republic of Kazakhstan, 29 June 2026

34.    EAG — 1st Regular Follow-up Report of the Republic of Kazakhstan (PDF)

35.    EAG — Outcomes of the 44th EAG Plenary meeting, Ashgabat, 19–23 May 2026

36.    FATF — Mutual Evaluation Report of the Republic of Kazakhstan, 2023 (PDF)

UPPERSETUP materials

37.    Permits and Notifications in Kazakhstan in 2026

38.    Digital Assets and Mining in Kazakhstan 2026

39.    LLP (TOO) in Kazakhstan for Foreigners 2026

40.    Opening a Bank Account in Kazakhstan for a Foreign Company and a Non-Resident

41.    Currency Control in Kazakhstan 2026

42.    AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026

43.    The UAE UBO Register and goAML

44.    Kazakhstan + UAE: The Dual Structure in 2026

45.    DNFBP AML Compliance in the UAE 2026

46.    Bankruptcy and Rehabilitation of Legal Entities in Kazakhstan in 2026

47.    Mandatory Audit and Financial Reporting in Kazakhstan in 2026

48.    Personal Data and Localisation in Kazakhstan in 2026

49.    The Hong Kong TCSP Licence in 2026

A note on sources. All provisions of Law No. 191-IV, the Code of Administrative Offences, the Criminal Code, Law No. 202-V and the subordinate acts are cited from the consolidated texts of the Ministry of Justice’s Adilet legal information system, read on 10 September 2026; the commencement dates of amendments are calculated from the first-official-publication dates given in the acts’ record cards and cross-checked against the notes in the Paragraph information system. Fines are converted into tenge at the 2026 MCI of KZT 4,325. AFM statistics for 2025 are taken from the official Akorda.kz statement; the figures on the number of SFMs and reports from the Concept for the Development of Financial Monitoring; the results of the international assessment from EAG and FATF publications. Law No. 191-IV contains no list of offshore zones for the threshold transaction under sub-paragraph 2) of paragraph 1 of Article 4: the dedicated Ministry of Finance list of 2010 was repealed with effect from 15 November 2020, and the list to be applied should be fixed in the ICR in the light of AFM guidance. Local boutique consulting and company-formation firms and aggregators were not used as sources. All links were checked on 10 September 2026.

Disclaimer

This material is for information purposes only and does not constitute legal, tax, financial, investment or consulting advice. Before taking any decision, individual professional advice should be obtained that takes into account the specific situation, the jurisdiction, the status of the company and the current requirements of the regulators.

Current as of September 2026.

Read more on the topic

All services on the platform

Everything you need to start and run a business - in one place

  • 2–10 days

    Company Setup

    Kazakhstan company with a complete set of incorporation documents


    Start
  • Monthly

    Accounting Services

    Accounting and Tax Compliance, Reporting, and Support in Accordance with Kazakhstan Requirements


  • 4–8 weeks

    Immigration Services

    Visas, Work Permits


  • 7–30 days

    Banking Services

    Corporate Bank Accounts in Kazakhstan and Payment Services


  • Custom timeline

    Permits and Licenses

    Business Licenses and Activity Permits


  • Custom timeline

    Legal Services

    Corporate Documents, Contracts, Compliance, Licensing, and Company Structure Changes